imPC@ndo EN

Vulnerabilità Microsoft

15.347 CVE

CVE-2008-0084
Alta 7.8

Unspecified vulnerability in the TCP/IP support in Microsoft Windows Vista allows remote DHCP servers to cause a denial of service (hang and restart) via a crafted DHCP packet.

microsoft windows_vista
0.74EPSS
CVE-2011-3389
Media 4.3

The SSL protocol, as used in certain configurations in Microsoft Windows and Microsoft Internet Explorer, Mozilla Firefox, Google Chrome, Opera, and other products, encrypts data by using CBC mode with chained initialization vectors, which allows man-in-the-mi…

canonical ubuntu_linux · debian debian_linux · google chrome · haxx curl · e altri 11
0.73EPSS
CVE-2016-7202
Alta 7.5

The scripting engines in Microsoft Internet Explorer 9 through 11 and Microsoft Edge allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Scripting Engine Memory Corruption Vulnerability…

microsoft edge
0.73EPSS
CVE-2004-0204
Alta 7.5

Directory traversal vulnerability in the web viewers for Business Objects Crystal Reports 9 and 10, and Crystal Enterprise 9 or 10, as used in Visual Studio .NET 2003 and Outlook 2003 with Business Contact Manager, Microsoft Business Solutions CRM 1.2, and oth…

bea weblogic_server · borland_software j_builder · businessobjects crystal_enterprise · businessobjects crystal_enterprise_java_sdk · e altri 5
0.73EPSS
CVE-2023-36039
Alta 8.0

Microsoft Exchange Server Spoofing Vulnerability

microsoft exchange_server
0.73EPSS
CVE-2016-0117
Alta 7.8

The PDF library in Microsoft Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allows remote attackers to execute arbitrary code via a crafted PDF document, aka "Windows Remote Code Execution Vulnerability."

microsoft windows_10 · microsoft windows_8.1 · microsoft windows_rt_8.1 · microsoft windows_server_2012
0.73EPSS
CVE-2020-1421
Alta 8.8

A remote code execution vulnerability exists in Microsoft Windows that could allow remote code execution if a .LNK file is processed.An attacker who successfully exploited this vulnerability could gain the same user rights as the local user, aka 'LNK Remote Co…

microsoft windows_10 · microsoft windows_server_2016 · microsoft windows_server_2019
0.73EPSS
CVE-2007-0038
Alta 9.3

Stack-based buffer overflow in the animated cursor code in Microsoft Windows 2000 SP4 through Vista allows remote attackers to execute arbitrary code or cause a denial of service (persistent reboot) via a large length value in the second (or later) anih block …

microsoft windows_2000 · microsoft windows_2003_server · microsoft windows_vista · microsoft windows_xp
0.73EPSS
CVE-2004-0899
Media 5.0

The DHCP Server service for Microsoft Windows NT 4.0 Server and Terminal Server Edition, with DHCP logging enabled, does not properly validate the length of certain messages, which allows remote attackers to cause a denial of service (application crash) via a …

microsoft windows_nt
0.73EPSS
CVE-2003-0001
Media 5.0

Multiple ethernet Network Interface Card (NIC) device drivers do not pad frames with null bytes, which allows remote attackers to obtain information from previous packets or kernel memory by using malformed packets, as demonstrated by Etherleak.

freebsd freebsd · linux linux_kernel · microsoft windows_2000 · microsoft windows_2000_terminal_services · e altri 1
0.73EPSS
CVE-1999-0256
Alta 7.5

Buffer overflow in War FTP allows remote execution of commands.

jgaa warftpd · microsoft windows_95 · microsoft windows_nt
0.72EPSS
CVE-2004-1134
Alta 10.0

Buffer overflow in the Microsoft W3Who ISAPI (w3who.dll) allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long query string.

microsoft w3who.dll
0.72EPSS
CVE-2014-0307
Alta 9.3

Use-after-free vulnerability in Microsoft Internet Explorer 9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a certain sequence of manipulations of a TextRange element, aka "Internet Explorer Memory Corru…

microsoft internet_explorer
0.72EPSS
CVE-2017-8740
Alta 7.5

Microsoft Edge in Microsoft Windows 10 1703 allows an attacker to execute arbitrary code in the context of the current user, due to the way that the Microsoft Edge scripting engine handles objects in memory, aka "Scripting Engine Memory Corruption Vulnerabilit…

microsoft edge
0.72EPSS
CVE-2017-8729
Alta 7.5

Microsoft Edge in Microsoft Windows 10 1703 allows an attacker to execute arbitrary code in the context of the current user, due to the way that the Microsoft Edge scripting engine handles objects in memory, aka "Scripting Engine Memory Corruption Vulnerabilit…

microsoft edge
0.72EPSS
CVE-2024-20697
Alta 7.3

Windows libarchive Remote Code Execution Vulnerability

microsoft windows_11_22h2 · microsoft windows_11_23h2 · microsoft windows_server_2022_23h2
0.72EPSS
CVE-2017-8636
Alta 7.5

Microsoft browsers in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allow an attacker to execute arbitrary code in the context of the …

microsoft edge · microsoft internet_explorer
0.72EPSS
CVE-2007-2815
Alta 10.0

The "hit-highlighting" functionality in webhits.dll in Microsoft Internet Information Services (IIS) Web Server 5.0 only uses Windows NT ACL configuration, which allows remote attackers to bypass NTLM and basic authentication mechanisms and access private web …

microsoft internet_information_services
0.72EPSS
CVE-2009-3672
Alta 9.3

Microsoft Internet Explorer 6 and 7 does not properly handle objects in memory that (1) were not properly initialized or (2) are deleted, which allows remote attackers to execute arbitrary code via vectors involving a call to the getElementsByTagName method fo…

microsoft internet_explorer
0.72EPSS
CVE-2010-3973
Alta 9.3

The WMITools ActiveX control in WBEMSingleView.ocx 1.50.1131.0 in Microsoft WMI Administrative Tools 1.1 and earlier in Microsoft Windows XP SP2 and SP3 allows remote attackers to execute arbitrary code via a crafted argument to the AddContextRef method, possi…

microsoft wmi_administrative_tools
0.72EPSS
CVE-2015-0072
Media 4.3

Cross-site scripting (XSS) vulnerability in Microsoft Internet Explorer 9 through 11 allows remote attackers to bypass the Same Origin Policy and inject arbitrary web script or HTML via vectors involving an IFRAME element that triggers a redirect, a second IFR…

microsoft internet_explorer
0.72EPSS
CVE-2006-0564
Alta 7.5

Stack-based buffer overflow in Microsoft HTML Help Workshop 4.74.8702.0, and possibly earlier versions, and as included in the Microsoft HTML Help 1.4 SDK, allows context-dependent attackers to execute arbitrary code via a .hhp file with a long Contents file f…

microsoft html_help · microsoft html_help_workshop
0.72EPSS
CVE-2017-8641
Alta 7.5

Microsoft browsers in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allow an attacker to execute arbitrary code in the context of the …

microsoft edge · microsoft internet_explorer
0.72EPSS
CVE-2016-7241
Alta 7.5

Microsoft Internet Explorer 11 and Microsoft Edge allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Microsoft Browser Memory Corruption Vulnerability."

microsoft edge · microsoft internet_explorer
0.71EPSS
CVE-2016-3247
Alta 7.5

Microsoft Internet Explorer 11 and Microsoft Edge allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Microsoft Browser Memory Corruption Vulnerability."

microsoft edge · microsoft internet_explorer
0.71EPSS